2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22818 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save |
| CVE-2024-22817 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte |
| CVE-2024-22603 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link |
| CVE-2024-22601 | HIGH | 8.8 | 0.2% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save |
| CVE-2024-22699 | HIGH | 8.8 | 0.4% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save. |
| CVE-2024-0607 | MEDIUM | 6.6 | 0.2% | Jan 18, 2024 | A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, wher... |
| CVE-2024-0409 | HIGH | 7.8 | 0.4% | Jan 18, 2024 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at crea... |
| CVE-2024-0408 | MEDIUM | 5.5 | 0.3% | Jan 18, 2024 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving... |
| CVE-2024-22593 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save |
| CVE-2024-22592 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update |
| CVE-2024-22591 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save. |
| CVE-2024-22568 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del. |
| CVE-2024-22549 | MEDIUM | 5.4 | 0.4% | Jan 18, 2024 | FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section. |
| CVE-2024-22548 | MEDIUM | 5.4 | 0.4% | Jan 18, 2024 | FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section. |
| CVE-2024-22317 | CRITICAL | 9.1 | 1.0% | Jan 18, 2024 | IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to ob... |
| CVE-2024-0669 | HIGH | 7.1 | 0.3% | Jan 18, 2024 | A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could stor... |
| CVE-2024-0580 | HIGH | 7.5 | 0.5% | Jan 18, 2024 | Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerabili... |
| CVE-2024-0381 | MEDIUM | 5.4 | 0.6% | Jan 18, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute... |
| CVE-2024-0655 | CRITICAL | 9.8 | 0.7% | Jan 18, 2024 | A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an ... |
| CVE-2024-0654 | HIGH | 7.8 | 0.3% | Jan 18, 2024 | A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Aff... |
| CVE-2024-0652 | MEDIUM | 4.8 | 0.6% | Jan 18, 2024 | A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affecte... |
| CVE-2024-0651 | HIGH | 7.2 | 0.6% | Jan 18, 2024 | A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affecte... |
| CVE-2024-23525 | MEDIUM | 6.5 | 0.8% | Jan 18, 2024 | The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option ... |
| CVE-2024-22416 | HIGH | 8.8 | 0.9% | Jan 18, 2024 | pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be mad... |
| CVE-2024-0650 | MEDIUM | 6.1 | 0.7% | Jan 18, 2024 | A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affect... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now